Moneycontrol PRO
HomeNewsTechnologyA flaw in WhatsApp may lock you out of your account

A flaw in WhatsApp may lock you out of your account

This WhatsApp security flaw may cause you to loose your account

April 13, 2021 / 16:54 IST
it was not for the CCI to decide if the Facebook-owned app's privacy policy was compliant with privacy norms, WhatsApp said. (Representative image)

The internet hasn't been a kind place lately and it feels like every other company is either getting hacked or their data stolen from right under their noses. But what happens when someone isn't interested in stealing your data but destroying it?

A new security flaw in WhatsApp's security system may allow a malicious actor to lock you out of your account and then delete it.

More alarming is the fact that to pull this off, you require only the victim's phone number. As reported on by Forbes, the way this works is by gaming security systems on WhatsApp.

When you install WhatsApp on a new phone, you may have noticed that it asks for your phone number and verifies it by sending a code by SMS. The problem is this phone number can be entered on any device that runs WhatsApp and the attacker simply has to fail the verification enough times for WhatsApp to shut down the codes for a period of 12 hours.

The only way you will know any of this is happening is by checking your messages and seeing lots of verification codes. WhatsApp itself will work just fine on your phone despite the amount of security codes you will suddenly start getting.

The moment WhatsApp puts a 12-hour lock on your account for failing the verification check too many times, the attacker then creates a new email id and sends a mail to support@whatsapp.com saying that they have lost their phone and would like their account to be deactivated.

The problem is there is no way for WhatsApp to know that the email isn't from you and there appear to be no follow-up questions either. The mail starts an automatic process and your WhatsApp account will then be placed in queue for deletion.

Now WhatsApp will show you a message saying that your account is locked and allow you to log back in if you verify your phone number. The problem? The system has already blocked codes being sent to your number for 12 hours.

Worse, the attacker can keep repeating the process for up to three times more, following which the WhatsApp security seems to break and the 12-hour lockdown perplexingly changes to -1 seconds. Now the system has stalled and there is no way for you to get back in.

This is too major a flaw to be present on platform that has 2 billion active users around the world. Make sure you have two-factor authentication turned on in the settings and if you have start receiving lots of verification codes all of a sudden, contact support immediately.

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

Moneycontrol News
first published: Apr 13, 2021 04:54 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347